Skip to main content
Article
Forensic triage for mobile phones with DEC0DE
USENIX Security Symposium (2011)
  • Robert Walls
  • Brian N. Levine
  • Erik G. Learned-Miller, University of Massachusetts - Amherst
Abstract

We present DEC0DE, a system for recovering information from phones with unknown storage formats, a critical problem for forensic triage. Because phones have myr- iad custom hardware and software, we examine only the stored data. Via flexible descriptions of typical data struc- tures, and using a classic dynamic programming algo- rithm, we are able to identify call logs and address book entries in phones across varied models and manufactur- ers. We designed DEC0DE by examining the formats of one set of phone models, and we evaluate its performance on other models. Overall, we are able to obtain high performance for these unexamined models: an average recall of 97% and precision of 80% for call logs; and average recall of 93% and precision of 52% for address books. Moreover, at the expense of recall dropping to 14%, we can increase precision of address book recovery to 94% by culling results that don’t match between call logs and address book entries on the same phone.

Disciplines
Publication Date
2011
Citation Information
Robert Walls, Brian N. Levine and Erik G. Learned-Miller. "Forensic triage for mobile phones with DEC0DE" USENIX Security Symposium (2011)
Available at: http://works.bepress.com/erik_learned_miller/52/